SecurityWeek’s weekly cybersecurity information roundup provides a concise overview of essential developments that won’t obtain full standalone protection but stay related to the broader menace panorama.
This curated abstract highlights key tales throughout vulnerability disclosures, rising assault strategies, coverage updates, business studies, and different noteworthy occasions to assist readers preserve a well-rounded consciousness of the evolving cybersecurity setting.
Listed below are this week’s highlights:
Dolphin X malware leverages AI to profile victims
Varonis Menace Labs found a brand new infostealer referred to as Dolphin X that makes use of an AI behavioral profiler to attain and prioritize contaminated customers based mostly on their exercise and put in software program. The malware targets greater than 300 functions, aiming to exfiltrate every little thing from browser passwords and cryptocurrency wallets to SSH keys and cloud tokens. An an infection on a developer’s machine may probably grant attackers entry to a whole manufacturing setting.
Abbott investigates hack
Abbott has disclosed a cybersecurity incident involving unauthorized entry to a restricted variety of programs inside its Most cancers Diagnostics enterprise. The corporate said that the breach has not disrupted enterprise operations, manufacturing, or affected person care. The infamous ShinyHunters group has taken credit score for the hack.
Cyberattack disrupts web companies throughout 23 Maine cities
A current cyberattack focusing on a telecommunications supplier in Maine resulted in widespread web service outages throughout 23 cities. The disruption impacted municipal networks and native authorities operations that depend on the regional telecom’s infrastructure.
Palo Alto Networks particulars exploit chain in Siemens ROX II switches
Unit 42 researchers recognized three zero-day vulnerabilities in Siemens ROX II OT switches that may be chained collectively to realize persistent root-level entry. By exploiting an arbitrary file disclosure flaw (CVE-2025-40948), an attacker can collect delicate system intelligence to facilitate a subsequent privilege escalation by way of command injection (CVE-2025-40947). The compromise is then cemented utilizing a 3rd vulnerability (CVE-2025-40949) within the net administration activity scheduler, permitting malicious code execution to outlive system reboots.
Ransomware gang calls for tens of millions from Swiss prepare producer Stadler
Swiss prepare producer Stadler Rail has refused to pay a ten million Swiss franc ($12 million) extortion demand from the Everest ransomware group following a focused information theft incident. The attackers breached a knowledge alternate platform shared with a provider in mid-July, stealing technical info with out impacting Stadler’s IT programs or world manufacturing operations. The corporate maintains that no vital safety or private information was compromised.
German authorities dismantle Kratos phishing group
German legislation enforcement authorities have efficiently dismantled the Kratos phishing group following a coordinated operation. The takedown disrupts a devoted cybercrime ring liable for organized credential theft and phishing campaigns.
A whole lot of Linux kernel vulnerabilities printed in large single-day drop
The cybersecurity group noticed an unprecedented launch of 432 CVEs associated to the Linux kernel inside a 24-hour interval. This large inflow of disclosures requires safety groups to quickly triage affected programs and consider patching priorities.
Google launches CodeMender preview
Google has launched the preview of CodeMender, a safety service designed to assist builders establish and remediate software program vulnerabilities extra effectively. The software integrates immediately into growth workflows to streamline discovering and patching insecure code earlier than it reaches manufacturing.
Russian APT Laundry Bear exploits Zimbra flaw in espionage marketing campaign
A joint advisory from CISA and worldwide companions warns {that a} Russian state-sponsored menace group, generally known as Laundry Bear, is actively exploiting a patched vulnerability (CVE-2025-66376) within the Zimbra Collaboration Suite. The attackers use a view-based exploit that triggers just by opening a malicious e mail, immediately exfiltrating the sufferer’s inbox. The espionage marketing campaign targets Western authorities and business entities to silently collect intelligence for Russia.
Supplier-installed safety gadgets expose tens of millions of automobiles to Bluetooth hijacking
Researchers at UC San Diego found a vulnerability in aftermarket anti-theft programs manufactured by Acrisure, leaving not less than 2.2 million automobiles prone to distant compromise. Attackers can exploit a hardcoded Bluetooth key from as much as 5 yards away to unlock doorways. Acrisure has since launched a patch to safe the affected KARR and SWDS gadgets, which have been put in primarily by dealerships in Southern California. “The vulnerability described within the analysis is extremely complicated and presents a low threat to prospects underneath real-world situations,” a KARR spokesperson advised The Register.
Associated: In Different Information: Iran Tracks US Navy Telephones, CrashStealer macOS Malware, CVD Blueprint
Associated: In Different Information: Canadian Hacker Jailed, Open Supply Zero-Days, Two Sentenced for ATM Jackpotting









